CVE-2026-85486: High severity Brocade ASCG vulnerability
Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade ASCGto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs basic authenticated access to Brocade ASCG and must be able to submit a configuration form. The attack does not require user interaction.
Which deployments are affected?
Brocade ASCG versions before 3.5.0 are affected. The available information does not state whether a default configuration exposes a reachable configuration form to basic users.
What is the impact of successful exploitation?
Crafted form input can be evaluated before validation, allowing arbitrary code execution on the server. An attacker could take control of the application, affecting its confidentiality, integrity, and availability.
How can administrators reduce exposure if they cannot upgrade immediately?
The provided information does not document a workaround. Restrict basic-user access to the application and configuration-form functionality where operationally possible, since authenticated access and form submission are prerequisites for exploitation.